Maestro & Unibot
ID: 42923727-0e5c-5df4-a6da-fd8ebbec19d7
STIX ID: report--42923727-0e5c-5df4-a6da-fd8ebbec19d7
Feed Name: CertiK Blog
In late October, attackers exploited missing access control in the Maestro and Unibot Telegram trading bot router contracts to perform arbitrary external calls and invoke transferFrom on users' pre-approved ERC-20 tokens. The two incidents affected 106 users and resulted in roughly $1.1M in losses after stolen tokens were swapped for ETH; the underlying flaw was an unprotected router function lacking permission and parameter checks, and users are advised to regularly check and revoke unnecessary token approvals.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
